Section 01
What each one actually does
Network segmentation is the discipline of splitting a flat network into smaller zones connected by software-defined rules. VLANs, firewalls between zones, SDN micro-segmentation, identity-based access — all variations on the same theme. The path between zones exists; the policy decides which packets cross it.
An air gap removes the path. There is no link between the isolated network and the rest of the world; if data must move between them, a human or a hardware switch carries it. The classical air gap is permanent (think SCIFs and classified networks). The kind AirGapNet implements is per-line and time-boxed — the gap is the default state, and a defined maintenance window is the exception.